Ghost Carriers Turn Telecom Trust Into Location Tracking
The weak point is not the phone. It is the trust between carriers. Surveillance vendors can pose as legitimate cellular providers, then use interconnect access to query location data across global networks. Standard defenses that focus on device security miss this operator-level abuse path.
Citizen Lab says it found two separate campaigns using fake “ghost” carriers and telecom signaling flaws to track victims worldwide. The report points to SS7, and to Diameter where protections are not fully deployed, with some cases falling back to SS7. The abuse ran through access to three telecom providers that repeatedly acted as the surveillance gateway.
The risk is persistent because the same signaling trust model still underpins global roaming and location lookups. As long as carriers accept weakly authenticated interconnect requests, location tracking remains available to operators that can buy or fake network access.
Surveillance campaigns use commercial surveillance tools to exploit long-known telecom vulnerabilities
Citizen Lab reveals how surveillance vendors exploit mobile network signaling protocols like SS7 and Diameter to track targets, highlighting severe global telecom risks.
Surveillance companies exploiting telecom system to spy on targets’ locations, research shows
The campaigns exploited a weakness in telecom infrastructure to allow the unnamed vendors to secretly pose as real cellular providers and pinpoint victims’ locations.